Dompdf / Dompdf
19 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-59941 | Dompdf: Uncontrolled resource consumption based on declared BMP dimensions | MEDIUM | 6.3 | Jul 28, 2026 |
| CVE-2026-59942 | Dompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps | MEDIUM | 6.3 | Jul 28, 2026 |
| CVE-2026-59943 | Dompdf: Embedded SVG images can leak existence of files and directories within the filesystem | MEDIUM | 6.3 | Jul 28, 2026 |
| CVE-2026-56722 | Dompdf: Local file read due to improper file path validation in SVG images encoded as data-URI | MEDIUM | 6.3 | Jul 28, 2026 |
| CVE-2026-55554 | Dompdf: Chroot Validation Bypass | LOW | 2.3 | Jul 28, 2026 |
| CVE-2026-55555 | Dompdf: File existence oracle via font-face stylesheet declaration | LOW | 2.3 | Jul 28, 2026 |
| CVE-2021-3902 | Improper Restriction of XML External Entity Reference in dompdf/dompdf | CRITICAL | 9.8 | Nov 15, 2024 |
| CVE-2021-3838 | PHAR Deserialization in dompdf/dompdf | CRITICAL | 9.8 | Nov 15, 2024 |
| CVE-2023-50262 | Dompdf possible DoS caused by infinite recursion when parsing SVG images | HIGH | 7.5 | Dec 13, 2023 |
| CVE-2023-24813 | URI validation failure on SVG parsing. Bypass of CVE-2023-23924 | CRITICAL | 10.0 | Feb 7, 2023 |
| CVE-2023-23924 | URI validation failure on SVG parsing in Dompdf | CRITICAL | 10.0 | Jan 31, 2023 |
| CVE-2022-41343 | registerFont in FontMetrics.php in Dompdf before 2.0.1 allows remote file inclusion because a URI validation failure does not halt font registration, as demons… | HIGH | 7.5 | Sep 25, 2022 |
| CVE-2022-2400 | External Control of File Name or Path in dompdf/dompdf | MEDIUM | 5.3 | Jul 18, 2022 |
| CVE-2022-0085 | Server-Side Request Forgery (SSRF) in dompdf/dompdf | MEDIUM | 5.3 | Jun 28, 2022 |
| CVE-2022-28368 | Dompdf 1.2.1 allows remote code execution via a .php file in the src:url field of an @font-face Cascading Style Sheets (CSS) statement (within an HTML input fi… | CRITICAL | 9.8 | Apr 3, 2022 |
| CVE-2014-5011 | DOMPDF before 0.6.2 allows Information Disclosure. | MEDIUM | 6.5 | Jan 10, 2020 |
| CVE-2014-5012 | DOMPDF before 0.6.2 allows denial of service. | MEDIUM | 6.5 | Jan 10, 2020 |
| CVE-2014-5013 | DOMPDF before 0.6.2 allows remote code execution, a related issue to CVE-2014-2383. | HIGH | 8.8 | Jan 10, 2020 |
| CVE-2014-2383 | dompdf.php in dompdf before 0.6.1, when DOMPDF_ENABLE_PHP is enabled, allows context-dependent attackers to bypass chroot protections and read arbitrary files… | MEDIUM | 6.8 | Apr 28, 2014 |
Showing 1 to 19 of 19 CVEs